Re: draft-ietf-krb-wg-kdc-model and OIDs

Leif Johansson <[email protected]> Tue, 31 Jul 2012 19:26:05 +0200
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 07/31/2012 06:39 PM, Leif Johansson wrote:
> On 07/31/2012 03:55 PM, Nico Williams wrote:
>> On Tue, Jul 31, 2012 at 3:49 AM, Sam Hartman 
>> <[email protected]> wrote:
>>> Why do we have these OIDs registered here? It seems like the
>>> OID should name a specific set of policy objects with well
>>> defined semantics and encoding. This draft doesn't get to that
>>> level of detail. Wouldn't it be better to defer that to schema
>>> and/or implementation documents?
> 
>> Agreed: this document doesn't specify LDAP schema, therefore it 
>> shouldn't allocate OIDs for LDAP schema.  Other metaschemas
>> might not require OIDs either, and anyways, it's really only LDAP
>> that we need OIDs for in the Internet standards context.
> 
>> Nico --
> 
> 
> I would tend to agree - but note that the information model
> includes an identifier as part of the attributes associated with a
> policy "object" so as it stands now, a schema has to assign some
> form of identifier.
> 
> If we drop the SHOULD requirement on the specific OIDs we could
> perhaps stick something like this in there before the list of
> standard policies:
> 
> "A policy is identified by a unique identifier. It is expected
> that implementations of this specification assign globally unique
> identifiers (eg an OID or URI) to the following standard policies
> in accordance with best-practice for identifier-management for the
> schema-language used:"
> 
> Cheers Leif
> 


Actually it turns out to be even simpler. I propose to change

"The use of OIDs is RECOMMENDED for this purpose."

with

"Implementations of this specification are expected to assign globally
unique identifiers to the list of standard policy below in accordance
with best-practice for identifier-management for the schema-language
used."

and then drop all of the <TBD>.n and "zero out" the IANA considerations.

	Cheers Leif


> 

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAlAYFS0ACgkQ8Jx8FtbMZnfWGwCfUM6BsTgNY2SjmES2nAS4eR1F
4RMAmgOngZ16An+aKDzBf5Ne+n59eeyX
=GCJC
-----END PGP SIGNATURE-----
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg